← back
CVE-2025-30355highobserved exploitationCWE-20

Synapse vulnerable to federation denial of service via malformed events

63Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 7.1epss 1.2%
from disclosure to weapon1 days
Published on NVDMar 27
1st PoC+1d
VulnCheckMar 26
exploitation probability
1.2%top 36% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Affected products
element-hq · synapse
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.